25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

NIST Proposes New Metric for Predicting Probability of Vulnerability Exploitation
May29

NIST Proposes New Metric for Predicting Probability of Vulnerability Exploitation

Patching software to fix known vulnerabilities is an endless process and one that is vital for cybersecurity; however, with so many vulnerabilities being discovered, it is a major challenge for security teams to keep on top of vulnerability management. In 2024, there was a 39% increase in Common Vulnerabilities and Exposures (CVEs), with 40,003 added to the National Vulnerability Database. For busy security teams, there is an inevitable delay in patching all instances of software to fix known exploited vulnerabilities and vulnerabilities that will likely be exploited in the wild, which gives threat actors a window of opportunity to conduct attacks. It is therefore important to ensure that patches are prioritized. Only a small number of disclosed vulnerabilities are ever exploited, so prioritizing patching can help to ensure the best use of resources to keep the window of opportunity as short as possible. One study suggests that only around 5% of vulnerabilities are exploited, while the monthly remediation rate at companies is around 16%. If the 16% of patched vulnerabilities...

Read More
Silent Ransom Group Targets U.S. Law Firms with Vishing Attacks
May28

Silent Ransom Group Targets U.S. Law Firms with Vishing Attacks

The Cyber Division of the Federal Bureau of Investigation (FBI) has issued a warning to U.S. law firms about targeted attacks by the Silent Ransom Group. Since Spring 2023, the group has been consistently targeting U.S. law firms, although it has also conducted attacks in many sectors, including healthcare. The Silent Ransom Group has been in operation since 2022 and engages in data theft and extortion, breaching company networks, exfiltrating sensitive data, and issuing ransom demands. The group threatens to sell the stolen data or publish it on its dark web data leak site if the ransom is not paid. The group is known to contact employees at the attacked company to pressure them into engaging in ransom negotiations. Law firms are being targeted as they hold large volumes of highly sensitive data, and are thought to be more likely to pay a ransom to prevent the sale or publication of stolen data. The Silent Ransom group primarily gains access to victims’ networks through callback phishing campaigns that impersonate companies such as Duolingo and Masterclass, and others that offer...

Read More
DME Company Owner Pleads Guilty to Participation in $30 Million Medicare Fraud Scheme
May28

DME Company Owner Pleads Guilty to Participation in $30 Million Medicare Fraud Scheme

The owner of multiple durable medical equipment companies has pleaded guilty to conspiracy to commit healthcare fraud after participating in a $30 million fraud scheme targeting Medicare beneficiaries and generating orders for unnecessary durable medical equipment such as back and knee braces that were billed to Medicare. Raju Sharma, 61, of Sharon, Massachusetts, is the owner of the durable medical equipment companies Pharmagears, LLC, and RR Medco, LLC. According to the U.S. Department of Justice, between February 2021 and February 2025, Sharma entered into contracts with telemarketing companies that were tasked with contacting Medicare beneficiaries and generating orders for orthotics that were not medically necessary, were often not wanted by the beneficiaries, or could not be used. The orders were generated on the basis of a phone call, without a medical practitioner meeting or examining the beneficiaries, and in some cases, orders were generated by using practitioners’ national provider identifiers without their knowledge or assent. Sharma was also alleged to have violated...

Read More
Key Systems Restored After Masimo Cyberattack
May28

Key Systems Restored After Masimo Cyberattack

Masimo has confirmed that it has made good progress recovering from the cyberattack it disclosed earlier this month. In its May 6, 2025, filing with the SEC, Masimo explained that the cyberattack had affected some of its manufacturing facilities, and was affecting its ability to process and fulfil orders; however, Masimo has now confirmed that its manufacturing facilities are working at near full capacity and its order taking and distribution and shipping systems are fully operational. The cyberattack did result in some delays to customers’ orders; however, by optimizing its systems, Masimo has ensured that all delayed orders are processed in a timely manner, and the company does not anticipate the incident harming its ability to meet existing orders and seasonal demand. Masimo holds a cyber insurance policy and expects it to cover the majority of the out-of-pocket costs incurred remediating the cyberattack, and does not believe the cyberattack will have any material impact on its fiscal 2025 revenue, which is expected to remain in the range of $1.5 billion to $1.53 billion....

Read More
Typical Roles within a Hospital Emergency Management Team
May27

Typical Roles within a Hospital Emergency Management Team

The roles within a hospital emergency management team can be much more extensive than emergency management roles in a non-medical organization. This is due to hospitals often having to respond to the needs of the community after an emergency in addition to managing its own environment. According to the Federal Emergency Management Agency (FEMA), most non-governmental organizations base their emergency management team structure on ICS-100 – an Incident Command System in which an Incident Commander is supported by Section Leaders from Operations, Planning, Logistics, and Finance/Admin, who each have support teams beneath them. Larger organizations and government agencies are more likely to adopt the military-style ICS-300 model for expanding incidents. In this model the Incident Commander has a small team reporting directly to him or her in addition to the Section Leaders. The roles beneath the Section Leader level are clearly defined and each role can be the responsibility of an individual or a department. HIPAA Training for Emergency Staff Staff need to understand how HIPAA...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist